Information about isafekrnlboot.sys

isafekrnlboot.sys

MD5: c604b5cfc9deaaa32691fc2798b86936
Size: 13 KB
First Published: 2017-05-21 06:07:03 (6 years ago)
Latest Published: 2018-09-06 19:06:17 (5 years ago)
Status: Clean (on last analysis)
Analysis Date: 2018-09-06 19:06:17 (5 years ago)
Signed By: Malwarebytes Corporation
Status: Valid
%system%\drivers
%system%
isafenetfilter.sys
isafekrnlboot.sys
iSafeKrnlBoot.sys
{55dce8ba-9dec-4013-937e-adbf9317d990}Gw64.sys
lace_wpf_x64.sys
netutils2016.sys
zdwfp64.sys
contentdefenderdrv.sys
wfdrvr_vw_1_10_0_28.sys
mpckpt.sys
kuaizipdrive.sys
{3b232d24-d5de-4194-b4d7-d53b41a09748}Gw64.sys
uefgdstor.sys
mwescontroller.sys
wpnfd_1_10_0_5.sys
lanmamaster.sys
cherimoya.sys
bsdriver.sys
wtmhdnkernel.sys
WFCRE.SYS
TMhardware.sys
{864fa5de-d926-4c45-89db-f59d06917be2}Gw64.sys
ppfd_vw_1_10_0_22.sys
MSIDNTFS.SYS
MPCKpt.sys
itdrvr_vw_1_10_0_25.sys
uefochubsrv.sys
kuaizipdrive2.sys
wwfd_vt_1_10_0_24.sys
powzip.sys
winmon.sys
30.4%
8.9%
8.0%
7.9%
4.9%
3.5%
3.5%
3.3%
3.1%
2.5%
2.3%
1.7%
1.7%
1.6%
1.5%
1.5%
1.5%
1.2%
0.9%
0.9%
0.9%
0.9%
0.9%
0.9%
0.7%
0.7%
0.6%
0.6%
0.6%
0.6%
0.4%
0.3%
0.3%
0.3%
0.3%
0.1%
0.1%
0.1%
Windows 10 92.9%
Windows 7 6.0%
Windows 8.1 1.2%
Subsystem: Native
PE Type: pe
OS Bitness: 64
Image Base: 0x0000000000010000
Entry Address: 0x00006124

PE Sections:

Name Size of data MD5
.text 2048 f6f86f932154e990accf86d83f2d546f
.rdata 512 d780c1848a4e43311f1524366bf1fd85
.data 512 043c46095689123e1f5be96c109c2f46
.pdata 512 720178380ff3ffd9ecdc2225b905d5ec
PAGE 512 2065f13d7e6ccf71073d5f7c911dcd61
INIT 1024 1d75f9adc1e1d84ec41be7a4c7bd3548

More information: